Skip to content

fix(automerge): merge only as the deploy-bot app and guard post-merge actor - #20

Merged
emkraan-deploy-bot[bot] merged 1 commit into
mainfrom
fix/automerge-app-token-only
Sep 27, 2026
Merged

emkraan-deploy-bot[bot] merged 1 commit into
mainfrom
fix/automerge-app-token-only

Conversation

@cmarko89

Copy link
Copy Markdown
Contributor

Root cause

emkraan-apps #1793 was merged as github-actions[bot] by automerge run 36076490388 (workflow_run). The App token minted fine and the App enabled native auto-merge earlier (run 36076462710). At 00:13:38 the App's direct mergePullRequest was refused with "Base branch was modified. Review and try the merge again." because a concurrent run (36076510468) had merged #1779 one second earlier. mutate() treated any App refusal as a reason to retry as GITHUB_TOKEN, and that retry merged 9d411fc as github-actions, so no push workflows (including deploy-image-revive) started.

Changes

  • App token is required: the mint step no longer has continue-on-error, and there is no || secrets.GITHUB_TOKEN fallback. No merge, auto-merge or enqueue mutation runs as GITHUB_TOKEN anywhere.
  • Transient refusals (base/head branch modified, try again) are retried up to 4 times as the App, re-reading the head oid each time.
  • Post-merge guard: after each merge this job makes, on pull_request: closed, and on every sweep for PRs merged in the last 24h (a GITHUB_TOKEN merge fires no closed run), the merge actor is checked. If it is github-actions[bot] and no push run exists for the merge commit, every active workflow with a matching push trigger (branch and paths / paths-ignore filters evaluated against the PR files) that declares workflow_dispatch is dispatched on the base branch, and the job emits an error and fails. Idempotent: skips workflows already dispatched since the merge.
  • GITHUB_TOKEN is still used to read the check rollup and to dispatch (workflow_dispatch is exempt from loop prevention). The caller template here now grants actions: write.

Follow-up

Fleet callers (including emkraan-apps automerge.yml, currently actions: read) need actions: write for the guard dispatch; without it the guard still errors loudly and lists the workflows to run by hand.

Refs Emkraan/emkraan-apps#1798

… actor

Remove every GITHUB_TOKEN merge path. The App token is now required (job fails if it
cannot be minted), transient merge refusals are retried as the App, and a post-merge
guard verifies the merge actor. A github-actions merge gets its push-triggered deploy
workflows dispatched and fails the job with a clear error. The sweep re-checks the last
24h of merges because a GITHUB_TOKEN merge fires no closed event.

Refs Emkraan/emkraan-apps#1798
@emkraan-deploy-bot
emkraan-deploy-bot Bot merged commit 803ed1a into main Sep 27, 2026
2 checks passed
@emkraan-deploy-bot
emkraan-deploy-bot Bot deleted the fix/automerge-app-token-only branch September 27, 2026 00:28
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant